First published: Thu Mar 27 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smackcoders Lead Form Data Collection to CRM allows Blind SQL Injection. This issue affects Lead Form Data Collection to CRM: from n/a through 3.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
smackcoders Lead Form Data Collection to CRM | <=3.0.1 | |
WordPress Lead Form Data Collection to CRM | <=3.0.1 |
Update the WordPress Lead Form Data Collection to CRM plugin to the latest available version (at least 3.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30810 is classified as a high severity vulnerability due to its potential for blind SQL injection.
To fix CVE-2025-30810, update the smackcoders Lead Form Data Collection to CRM plugin to version 3.0.2 or later.
CVE-2025-30810 affects versions up to and including 3.0.1 of the Lead Form Data Collection to CRM plugin.
CVE-2025-30810 is an SQL injection vulnerability that allows for blind SQL injection attacks.
If your website uses versions of the Lead Form Data Collection to CRM plugin up to 3.0.1, it is vulnerable to CVE-2025-30810.